V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2005-3627
DEB
High

Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to m…

CVSS
7.5
High
EPSS
0.05
p91
Published
2005-01-01
Updated
2005-01-01
Description

Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo.

Tags · CWE
RCE
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Xpdf
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2005-01-01
Published
2005-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.054 · p91
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
cupsTracked
cupsTracked
cupsTracked
cupsysTracked
gpdfTracked
gpdfTracked
kdegraphicsTracked
kdegraphicsTracked
kofficeTracked
libextractorTracked
pdfkit.frameworkTracked
pdftohtmlTracked
popplerTracked
tetexTracked
tetexTracked
tetex-binTracked
xpdfTracked
xpdfTracked
xpdfTracked
xpdf*Tracked
Source databases
DEB
CVE
RED
Related vulnerabilities